8 Sep 08:50 2014
key validation rules for today
elijah <elijah <at> riseup.net>
2014-09-08 06:50:36 GMT
2014-09-08 06:50:36 GMT
The threads here on key validation have been quite productive, but many of the new email projects have need for some actual rules we can implement in the here and now [1]. Most of these projects plan to implement some form of TOFU, but there are many ways this could be done and many ways this could transition to better key validation in the future. Here is a draft text for some basic rules to navigate this transition. https://pad.riseup.net/p/key-validation That link is live editable. Please comment, edit, deplore, or applaud as you see fit. The full text is also included below for your convenience. -elijah [1] https://github.com/OpenTechFund/secure-email ---- begin ---- Transitional rules for automated key validation Intro =================================== Although many interesting key validation infrastructure schemes have been recently proposed, it is not at all clear what someone writing secure email software today should do. In particular, most of the new opportunistic encrypted email projects have proposed starting with some sort of Trust On First Use, but there are many ways to implement TOFU and many ways TOFU can interact with whatever more advanced schemes are(Continue reading)
RSS Feed